Out-of-Bounds Read Vulnerability in GStreamer by GStreamer Developers
CVE-2021-3522

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 June 2021

What is CVE-2021-3522?

An out-of-bounds read vulnerability exists in GStreamer versions prior to 1.18.4, which may occur while processing specific ID3v2 tags. This flaw may allow attackers to exploit this condition to potentially access sensitive information or cause unintended behavior in applications relying on GStreamer for multimedia processing. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

GStreamer All GStreamer version before 1.18.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.